DataFlex
DataFlex
Working with PEM Encrypted Private Keys
See more PEM Examples
Demonstrates how to load and save PEM encrypted private keys.Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Boolean iSuccess
Handle hoPem
String sPemPassword
Handle hoFac
String sPemText
Integer i
Integer iNumPrivateKeys
Variant vPrivKey
Handle hoPrivKey
String sTemp1
Integer iTemp1
Move False To iSuccess
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
Move False To iSuccess
Get Create (RefClass(cComChilkatPem)) To hoPem
If (Not(IsComObjectCreated(hoPem))) Begin
Send CreateComObject of hoPem
End
Move "secret" To sPemPassword
// To load a PEM file containing encrypted private keys, simply
// provide the password.
Get ComLoadPemFile Of hoPem "/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem" sPemPassword To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoPem To sTemp1
Showln sTemp1
Procedure_Return
End
Get Create (RefClass(cComCkFileAccess)) To hoFac
If (Not(IsComObjectCreated(hoFac))) Begin
Send CreateComObject of hoFac
End
Get ComReadEntireTextFile Of hoFac "/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem" sPemPassword To sPemText
// To load a PEM from a string, call LoadPem instead of LoadPemFile:
Get ComLoadPem Of hoPem sPemText To iSuccess
If (iSuccess = False) Begin
Get ComLastErrorText Of hoPem To sTemp1
Showln sTemp1
Procedure_Return
End
// A few notes:
// The PEM may contain both private keys and certificates (or anything else).
// The password is utilized for whatever content in the PEM is encrypted.
// It is OK to have both encrypted and non-encrypted content within a given PEM.
// PEM private keys can be encrypted in different formats. The LoadPem and LoadPemFile
// methods automatically handle the different formats.
// One format is PKCS8 and is indicated by this delimiter within the PEM:
// -----BEGIN ENCRYPTED PRIVATE KEY-----
// MIICoTAbBgkqhkiG9w0BBQMwDgQIfdD0zv24lgkCAggABIICgE0PdHJmRbNs6cBX
// ...
// Another format, we'll call "passphrase" looks like this in the PEM:
// -----BEGIN RSA PRIVATE KEY-----
// Proc-Type: 4,ENCRYPTED
// DEK-Info: DES-EDE3-CBC,A4215544D11C5D0C
//
// paqy9XRexcSjurHfG0xhCaUD0HrvIdhuC0CbRxxxeMlkLaV6+uT80rBxt2AaibWG
// ...
// Show the bit length of each private key:
Get ComNumPrivateKeys Of hoPem To iNumPrivateKeys
If (iNumPrivateKeys = 0) Begin
Showln (("Error: Expected the PEM to contain private keys."))
Procedure_Return
End
Get Create (RefClass(cComChilkatPrivateKey)) To hoPrivKey
If (Not(IsComObjectCreated(hoPrivKey))) Begin
Send CreateComObject of hoPrivKey
End
For i From 1 To iNumPrivateKeys
Get pvComObject of hoPrivKey to vPrivKey
Get ComPrivateKeyAt Of hoPem (i - 1) vPrivKey To iSuccess
Get ComBitLength Of hoPrivKey To iTemp1
Showln i ": " iTemp1 " bits"
Loop
End_Procedure